Open Cloud credentials are missing, invalid, or lack permissions
Repair the scoped Roblox User API Key used by Clan Labs rank and pending-join workflows.
Last updatedSymptom
Clan Labs says Roblox Open Cloud is not configured, the credential is invalid, a group write is forbidden, or rank and pending-join actions fail while read-only dashboard features still work.
Most likely causes
- No Open Cloud User API Key is saved for the community.
- The key expired, was revoked, or was copied incorrectly.
- The key does not include the intended Roblox group.
groupsaccess is missinggroup:readorgroup:write.- An IP restriction excludes Clan Labs.
- A different secret, such as a Clan Labs API key, was entered.
Diagnostic checks
- Open Settings → Roblox Open Cloud as SuperOwner.
- Check whether Clan Labs shows a configured credential; it will not reveal the secret again.
- In Roblox Creator Hub, inspect the key’s group resource, operations, expiry, and IP restrictions.
- Confirm the numeric group ID matches this community.
- Determine whether reads, writes, or both fail.
Resolution
Create a replacement Roblox User API Key with the intended group under groups, allow group:read and group:write, and do not add an IP restriction. Set an expiry only if you can rotate the key before it ends. Save it once in the Clan Labs Open Cloud form, then revoke the old key in Roblox.
A Clan Labs cl_live_ API key cannot replace a Roblox Open Cloud key.
When to retry
Test one low-risk read or authorised test-member action after saving the replacement. Following an uncertain rank write, check Roblox’s current rank before retrying.
Contact support
Contact Clan Labs support when the resource and operations are correct but Clan Labs still rejects a freshly created key.
Include this information
Include community and Roblox group IDs, failed action, exact error, key creation and test times, and a redacted screenshot of resource and operation names. Never include the key value.